PaperCut updated its urgent security advisory on August 31, 2026 for actively exploited vulnerabilities affecting PaperCut NG and PaperCut MF, two print management products used in business, education, healthcare, legal, and government environments. The company says all versions are potentially affected and that Emergency Patch Release 2 is available for versions 24, 25, and 26 while work continues toward an official release.
The practical issue for owners is simple: a print server is rarely just a printer problem. It may touch user accounts, scanning workflows, file paths, card or ID lookups, internal directories, and documents that pass through ordinary office operations. When that system has been exposed to the internet or left unreviewed after an emergency patch, the risk can move well beyond paper jams and toner jokes.
The business decision behind the patch
PaperCut's advisory says customers with public-facing PaperCut NG/MF application servers should immediately restrict web access to Praktyczny szczegół ITed IP addresses. The advisory also lists two issues: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, a critical unsafe dynamic class loading flaw. SecurityWeek reported the vulnerabilities have been exploited against users, and The Hacker News reported that researchers described a chain from authentication bypass to remote code execution.
That means a completed ticket that only says patched may not be enough. The owner-level decision is whether the business should accept a basic update confirmation or require evidence that the system was not publicly reachable, that the correct emergency release or upgrade path was applied, and that compromise indicators were reviewed before normal service resumed.
What owners should ask their IT provider
- Do we run PaperCut NG or PaperCut MF anywhere? Include primary application servers, site servers, secondary print servers, old virtual machines, and systems maintained by a copier or print vendor.
- Was any PaperCut web interface exposed to the public internet? If yes, ask when access was restricted and whether the change was verified from outside the network.
- Which version or emergency patch is now installed? PaperCut recommends Emergency Patch Release 2 for affected v24, v25, and v26 environments that need the emergency patch.
- Were logs and indicators of compromise checked? PaperCut lists suspicious log entries, missing or truncated logs, unusual child processes from the PaperCut application, unexpected remote access tools, and other signs that deserve review.
- Were secondary and site servers included? PaperCut's Częste pytania says site servers and secondary or print servers should be updated to a patched version, not just the primary application server.
- What is the rebuild threshold? If compromise is suspected, PaperCut recommends securing current backups, rebuilding the application server, restoring from a clean backup taken before suspicious behavior, and activating incident response procedures.
A practical next step
Ask for a short written PaperCut exposure review. It should state whether PaperCut is present, which systems were checked, whether internet access was restricted, what version or emergency patch is installed, which logs and services were reviewed, and whether any third-party copier, print, or MSP vendor owns part of the environment.
For many New Jersey businesses, schools, nonprofits, and healthcare practices, that review can be finished quickly if the environment is simple. The important part is making the evidence match the risk. A print server may live in the background, but when it is under active exploitation, it deserves a front-desk level of attention.
Sources and further reading